exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 28 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 28
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Which two attributes are required on a certificate so it can be used as a CA certificate on SSL inspection? (Choose two.)

  • A. The keyUsage extension must be set to keyCertSign.
  • B. The CA extension must be set to TRUE.
  • C. The issuer must be a public CA.
  • D. The common name on the subject field must use a wildcard name.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
itmaxuser
Highly Voted 1 year, 6 months ago
The CA=True value identifies the certificate as a CA certificate. The KryUsage =KeyCertSign value indicates that the certificate corresponding private key is permitted to sign certificates. see RFC 5280 section 4.2.1.9 basic Constraints. Answer is A and B
upvoted 6 times
...
Viicon
Most Recent 3 months, 3 weeks ago
Is this the same exam as the FCP_FGT-AD_7.4 Administrator?
upvoted 1 times
...
Slash_JM
1 year, 3 months ago
Selected Answer: AB
FortiGate Security 7.2 Study Guide p.232
upvoted 1 times
...
raydel92
1 year, 4 months ago
Selected Answer: AB
A. The keyUsage extension must be set to keyCertSign. B. The CA extension must be set to TRUE. Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 3 times
...
[Removed]
1 year, 5 months ago
Selected Answer: AB
Correct answers: AB
upvoted 1 times
...
mcclane654
1 year, 6 months ago
Selected Answer: AB
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Add-a-new-certificate-to-SSL-SSH-inspection/ta-p/251252
upvoted 2 times
...
umairmasood
1 year, 6 months ago
A & B are true. can verify over site
upvoted 1 times
...
Eggrolls
1 year, 6 months ago
Selected Answer: AB
A & B FortiGate_Security_7.2 page 232 Although it appears as though the user browser is connected to the web server, the browser is connected to FortiGate. FortiGate is acting as a proxy web server. In order for FortiGate to act in these roles, its CA certificate must have the basic constraints extension set to cA=True and the value of the keyUsage extension set to keyCertSign.
upvoted 4 times
...
redSTORM
1 year, 8 months ago
Selected Answer: AB
Correct Answer: AB
upvoted 1 times
...
PaulGo
1 year, 9 months ago
Selected Answer: AB
Security page 323 its CA certificate must have the basic constrainst extension set to cA=True and the value of the keyUsage extension set to keyCertSing
upvoted 2 times
...
BoostBoris
1 year, 11 months ago
Selected Answer: AB
Full SSL inspection - Certificate requirements: FortiGate is acting as a proxy web server. In order for FortiGate to act in these roles, its CA certificate must have the basic constraints extension set to cA=True and the value of the keyUsage extension set to keyCertSign
upvoted 2 times
...
chromevandium11
2 years ago
Selected Answer: AB
AB is correct.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago